Crisis Management & Incident Response Flashcards
7 cards from real CSC practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Crisis Management & Incident Response flashcards as text
Which containment strategy is most appropriate when an organization cannot afford any business disruption during an active incident?
Answer: Short-term containment with monitoring while maintaining operations
Short-term containment allows the organization to maintain operations while limiting the spread of an incident through monitoring and targeted controls.
An attacker uses a compromised employee account to exfiltrate data over several weeks. Which detection control would MOST likely have identified this earliest?
Answer: User and Entity Behavior Analytics (UEBA)
UEBA detects anomalous behavior patterns compared to a user's baseline, making it effective at catching insider threats and compromised accounts.
What is the key difference between a disaster recovery plan (DRP) and a business continuity plan (BCP)?
Answer: DRP covers IT systems recovery; BCP covers broader operational continuity during disruption
A DRP focuses on restoring IT systems and data after a disaster, while a BCP encompasses maintaining all critical business functions during and after disruption.
When performing memory forensics during incident response, which tool is commonly used to acquire volatile memory from a live Windows system?
Answer: WinPmem or DumpIt
WinPmem and DumpIt are widely used tools for capturing a raw memory image from live Windows systems without shutting them down.
A CISO receives a threat intelligence report indicating a zero-day vulnerability is being actively exploited against their industry. What is the BEST immediate crisis response action?
Answer: Activate the incident response team and apply compensating controls while awaiting a patch
Activating the IR team and deploying compensating controls (such as WAF rules or network segmentation) provides immediate protection while waiting for an official vendor patch.
Which type of malware analysis involves executing a sample in an isolated environment to observe its behavior?
Answer: Dynamic analysis
Dynamic analysis executes malware in a controlled sandbox to observe real-time behavior such as network connections, file modifications, and registry changes.
What does the term 'scope creep' mean in the context of incident response?
Answer: The gradual expansion of an investigation beyond its original boundaries
Scope creep in incident response refers to an investigation gradually expanding beyond its originally defined boundaries, consuming additional resources and time.